99.7% of firms have AI access policies, yet 87% saw agents reach sensitive data
daniel_tenuo · reddit · 2026-10-09
A Delinea survey found 99.7% of respondents have formal AI access policies, yet 87% still reported an AI tool or agent reaching data it shouldn't. The author argues written policy rarely becomes a hard runtime boundary: a prompt telling an agent to work only on customer 4471 means nothing if its service token opens every customer. The post explores where the enforcement gap comes from, why subagents make it worse, and why scope must be enforced before an action runs.
More from coding & agent
- Photon gives iMessage agents a phone book to discover and add each other to group chats — SucceededMind · 2026-10-09
- AI-coded software's biggest problem is maintainership — let agents take it over — mark_k · 2026-10-09
- Matthew Berman shares his AI setup: nearly everything in Codex, ChatGPT barely used — MatthewBerman · 2026-10-09
- Higgsfield Launches Katana, an AI Video Editing Tool Inside Claude via MCP — aakashgupta · 2026-10-09
- a16z: Agents burn 5x the tokens of humans, up 14x in six months as AWS rewires for machine users — a16z · 2026-10-09
- Designing evals for AI contract review: ten lawyers, ten different redlines — graceisford · 2026-10-09